4.1 | Structure of this document | 12 |
4.2 | Application of ISO/IEC 27001:2013 requirements | 10 |
4.3 | Application of ISO/IEC 27002:2013 guidelines | 10 |
4.4 | Customer | 12 |
5.2 | Context of the organization | 16 |
5.2.1 | Understanding the organization and its context | 39 |
5.2.2 | Understanding the needs and expectations of interested parties | 25 |
5.2.3 | Determining the scope of the information security management system | 11 |
5.2.4 | Information security management system | 20 |
5.3 | Leadership | 14 |
5.3.1 | Leadership and commitment | 42 |
5.3.2 | Policy | 13 |
5.3.3 | Organizational roles, responsibilities and authorities | 45 |
5.4 | Planning | 8 |
5.4.1 | Actions to address risks and opportunities | 48 |
5.4.2 | Information security objectives and planning to achieve them | 4 |
5.5 | Support | 4 |
5.5.1 | Resources | 6 |
5.5.2 | Competence | 22 |
5.5.3 | Awareness | 23 |
5.5.4 | Communication | 38 |
5.5.5 | Documented information | 44 |
5.6 | Operation | 7 |
5.6.1 | Operational planning and control | 32 |
5.6.2 | Information security risk assessment | 29 |
5.6.3 | Information security risk treatment | 22 |
5.7 | Performance evaluation | 8 |
5.7.1 | Monitoring, measurement, analysis and evaluation | 46 |
5.7.2 | Internal audit | 50 |
5.7.3 | Management review | 47 |
5.8 | Improvement | 9 |
5.8.1 | Nonconformity and corrective action | 46 |
5.8.2 | Continual improvement | 47 |
6.10 | Communications security | 9 |
6.10.1 | Network security management | 27 |
6.10.2 | Information transfer | 27 |
6.11 | Systems acquisition, development and maintenance | 9 |
6.11.1 | Security requirements of information systems | 23 |
6.11.2 | Security in development and support processes | 22 |
6.11.3 | Test data | 16 |
6.12 | Supplier relationships | 11 |
6.12.1 | Information security in supplier relationships | 22 |
6.12.2 | Supplier service delivery management | 19 |
6.13 | Information security incident management | 15 |
6.13.1 | Management of information security incidents and improvements | 26 |
6.14 | Information security aspects of business continuity management | 6 |
6.14.1 | Information security continuity | 22 |
6.14.2 | Redundancies | 13 |
6.15 | Compliance | 10 |
6.15.1 | Compliance with legal and contractual requirements | 22 |
6.15.2 | Information security reviews | 29 |
6.2 | Information security policies | 20 |
6.2.1 | Management direction for information security | 34 |
6.3 | Organization of information security | 10 |
6.3.1 | Internal organization | 21 |
6.3.2 | Mobile devices and teleworking | 22 |
6.4 | Human resource security | 7 |
6.4.1 | Prior to employment | 22 |
6.4.2 | During employment | 24 |
6.4.3 | Termination and change of employment | 21 |
6.5 | Asset management | 13 |
6.5.1 | Responsibility for assets | 21 |
6.5.2 | Information classification | 28 |
6.5.3 | Media handling | 23 |
6.6 | Access control | 37 |
6.6.1 | Business requirements of access control | 22 |
6.6.2 | User access management | 27 |
6.6.3 | User responsibilities | 23 |
6.6.4 | System and application access control | 22 |
6.7 | Cryptography | 10 |
6.7.1 | Cryptographic controls | 26 |
6.8 | Physical and environmental security | 10 |
6.8.1 | Secure areas | 21 |
6.8.2 | Equipment | 22 |
6.9 | Operations security | 9 |
6.9.1 | Operational procedures and responsibilities | 27 |
6.9.2 | Protection from malware | 29 |
6.9.3 | Backup | 22 |
6.9.4 | Logging and monitoring | 33 |
6.9.5 | Control of operational software | 20 |
6.9.6 | Technical vulnerability management | 26 |
6.9.7 | Information systems audit considerations | 18 |
7.2 | Conditions for collection and processing | 15 |
7.2.1 | Identify and document purpose | 14 |
7.2.2 | Identify lawful basis | 15 |
7.2.3 | Determine when and how consent is to be obtained | 10 |
7.2.4 | Obtain and record consent | 8 |
7.2.5 | Privacy impact assessment | 23 |
7.2.6 | Contracts with PII processors | 21 |
7.2.7 | Joint PII controller | 9 |
7.2.8 | Records related to processing PII | 22 |
7.3 | Obligations to PII principals | 14 |
7.3.1 | Determining and fulfilling obligations to PII principals | 11 |
7.3.10 | Automated decision making | 12 |
7.3.2 | Determining information for PII principals | 11 |
7.3.3 | Providing information to PII principals | 12 |
7.3.4 | Providing mechanism to modify or withdraw consent | 9 |
7.3.5 | Providing mechanism to object to PII processing | 10 |
7.3.6 | Access, correction and/or erasure | 17 |
7.3.7 | PII controllers' obligations to inform third parties | 10 |
7.3.8 | Providing copy of PII processed | 10 |
7.3.9 | Handling requests | 13 |
7.4 | Privacy by design and privacy by default | 20 |
7.4.1 | Limit collection | 17 |
7.4.2 | Limit processing | 17 |
7.4.3 | Accuracy and quality | 24 |
7.4.4 | PII minimization objectives | 17 |
7.4.5 | PII de-identification and deletion at the end of processing | 24 |
7.4.6 | Temporary files | 10 |
7.4.7 | Retention | 23 |
7.4.8 | Disposal | 24 |
7.4.9 | PII transmission controls | 27 |
7.5 | PII sharing, transfer, and disclosure | 14 |
7.5.1 | Identify basis for PII transfer between jurisdictions | 22 |
7.5.2 | Countries and international organizations to which PII can be transferred | 21 |
7.5.3 | Records of transfer of PII | 24 |
7.5.4 | Records of PII disclosure to third parties | 13 |
8.2 | Conditions for collection and processing | 19 |
8.2.1 | Customer agreement | 16 |
8.2.2 | Organization’s purposes | 11 |
8.2.3 | Marketing and advertising use | 8 |
8.2.4 | Infringing instruction | 6 |
8.2.5 | Customer obligations | 9 |
8.2.6 | Records related to processing PII | 10 |
8.3 | Obligations to PII principals | 5 |
8.3.1 | Obligations to PII principals | 12 |
8.4 | Privacy by design and privacy by default | 16 |
8.4.1 | Temporary files | 16 |
8.4.2 | Return, transfer or disposal of PII | 23 |
8.4.3 | PII transmission controls | 26 |
8.5 | PII sharing, transfer, and disclosure | 7 |
8.5.1 | Basis for PII transfer between jurisdictions | 9 |
8.5.2 | Countries and international organizations to which PII can be transferred | 10 |
8.5.3 | Records of PII disclosure to third parties | 18 |
8.5.4 | Notification of PII disclosure requests | 11 |
8.5.5 | Legally binding PII disclosures | 11 |
8.5.6 | Disclosure of subcontractors used to process PII | 12 |
8.5.7 | Engagement of a subcontractor to process PII | 17 |
8.5.8 | Change of subcontractor to process PII | 10 |